Real-Time Detection of Dictionary DGA Network Traffic Using Deep Learning

被引:0
|
作者
Highnam K. [1 ]
Puzio D. [2 ]
Luo S. [3 ]
Jennings N.R. [1 ]
机构
[1] Imperial College London, London
[2] Kensho Technologies, McLean, VA
[3] Tencent, Shenzhen
关键词
Botnets; Deep learning; Domain generation algorithm; Malware; Network security; Neural networks;
D O I
10.1007/s42979-021-00507-w
中图分类号
学科分类号
摘要
Botnets and malware continue to avoid detection by static rule engines when using domain generation algorithms (DGAs) for callouts to unique, dynamically generated web addresses. Common DGA detection techniques fail to reliably detect DGA variants that combine random dictionary words to create domain names that closely mirror legitimate domains. To combat this, we created a novel hybrid neural network, Bilbo the “bagging” model, that analyses domains and scores the likelihood they are generated by such algorithms and therefore are potentially malicious. Bilbo is the first parallel usage of a convolutional neural network (CNN) and a long short-term memory (LSTM) network for DGA detection. Our unique architecture is found to be the most consistent in performance in terms of AUC, F1 score, and accuracy when generalising across different dictionary DGA classification tasks compared to current state-of-the-art deep learning architectures. We validate using reverse-engineered dictionary DGA domains and detail our real-time implementation strategy for scoring real-world network logs within a large enterprise. In 4 h of actual network traffic, the model discovered at least five potential command-and-control networks that commercial vendor tools did not flag. © 2021, The Author(s).
引用
收藏
相关论文
共 50 条
  • [41] Real-Time Network Anomaly Detection System Using Machine Learning
    Zhao, Shuai
    Chandrashekar, Mayanka
    Lee, Yugyung
    Medhi, Deep
    2015 11TH INTERNATIONAL CONFERENCE ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS (DRCN), 2015, : 267 - 270
  • [42] Graph Spatiotemporal Pattern Learning Network for Real-Time Road Network Traffic Abnormal Incident Detection
    Li, Haitao
    Ma, Yongjian
    Wang, Xin
    Li, Zhihui
    TRANSPORTATION RESEARCH RECORD, 2023, 2677 (12) : 815 - 829
  • [43] Real-time Traffic Analysis Using Deep Learning Techniques And UAV Based Video
    Zhang, Huaizhong
    Liptrott, Mark
    Bessis, Nik
    Cheng, Jianquan
    2019 16TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED VIDEO AND SIGNAL BASED SURVEILLANCE (AVSS), 2019,
  • [44] Real-Time Surveillance Using Deep Learning
    Iqbal, Muhammad Javed
    Iqbal, Muhammad Munwar
    Ahmad, Iftikhar
    Alassafi, Madini O.
    Alfakeeh, Ahmed S.
    Alhomoud, Ahmed
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [45] Real-Time Detection of Intrusive Traffic in QoS Network Domains
    Ahmed, Abdulghani Ali
    Jantan, Aman
    Wan, Tat-Chee
    IEEE SECURITY & PRIVACY, 2013, 11 (06) : 45 - 53
  • [46] SafeSmartDrive: Real-Time Traffic Environment Detection and Driver Behavior Monitoring With Machine and Deep Learning
    Bouhsissin, Soukaina
    Sael, Nawal
    Benabbou, Faouzia
    Soultana, Abdelfettah
    Jannani, Ayoub
    IEEE ACCESS, 2024, 12 : 169499 - 169517
  • [47] Real-Time Anomaly Detection of Network Traffic Based on CNN
    Liu, Haitao
    Wang, Haifeng
    SYMMETRY-BASEL, 2023, 15 (06):
  • [48] Real-time Traffic Congestion Detection with SIGHTA Regression Network
    Jiang, Long
    Wang, Yatao
    Zhao, Ying
    PROCEEDINGS OF 2019 IEEE 9TH INTERNATIONAL CONFERENCE ON ELECTRONICS INFORMATION AND EMERGENCY COMMUNICATION (ICEIEC 2019), 2019, : 45 - 50
  • [49] Real-time traffic allocation using learning automata
    Economides, AA
    SMC '97 CONFERENCE PROCEEDINGS - 1997 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS, VOLS 1-5: CONFERENCE THEME: COMPUTATIONAL CYBERNETICS AND SIMULATION, 1997, : 3307 - 3312
  • [50] Real-Time Lane Detection Based on Deep Learning
    Sun-Woo Baek
    Myeong-Jun Kim
    Upendra Suddamalla
    Anthony Wong
    Bang-Hyon Lee
    Jung-Ha Kim
    Journal of Electrical Engineering & Technology, 2022, 17 : 655 - 664